Dasanzhone's vulnerability footprint concentrates in a focused line of GPON optical network interface devices and their firmware, which serve as access points in broadband delivery infrastructure. The observed weakness classes—authorization bypass through user-controlled keys, cross-site scripting in web interfaces, and command injection—reflect the authentication and input-handling exposure typical of network appliances with embedded management interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dasanzhone over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9118HIGH The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhn | Oct 17, 2017 | 8.8 | 64 | NO | YES |
CVE-2014-8357HIGH backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user | Oct 17, 2017 | 8.8 | 36 | NO | YES |
CVE-2014-8356HIGH The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related t | Nov 21, 2019 | 8.8 | 35 | NO | YES |
CVE-2019-10677MEDIUM Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript v | Sep 5, 2019 | 6.1 | 34 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dasanzhone.
Media articles that mention a CVE ID that affects a product developed by Dasanzhone — matched by CVE ID, not by vendor name.